HCISPP · Question #265
You are provided a network vulnerability scan of the hospital network. There are numerous critical unpatched vulnerabilities on many of the devices. You work with the person who runs the centralized…
The correct answer is C. Exclude medical devices from the updates. Medical devices (e.g., infusion pumps, ventilators, imaging systems) are FDA-regulated and operate under strict vendor certifications. Applying unauthorized or automated patches to medical devices can void FDA clearance, break proprietary firmware, disrupt life-critical…
Question
You are provided a network vulnerability scan of the hospital network. There are numerous critical unpatched vulnerabilities on many of the devices. You work with the person who runs the centralized vulnerability patching team to develop a remediation approach that includes automated security patching of systems. Which of these steps would you take next?
Options
- AContact system owners to advise them of the updates.
- BSchedule the remediation patching after clinical hours.
- CExclude medical devices from the updates.
- DQuarantine vulnerable systems per policy.
How the community answered
(33 responses)- A12% (4)
- B6% (2)
- C79% (26)
- D3% (1)
Explanation
Medical devices (e.g., infusion pumps, ventilators, imaging systems) are FDA-regulated and operate under strict vendor certifications. Applying unauthorized or automated patches to medical devices can void FDA clearance, break proprietary firmware, disrupt life-critical functionality, or violate regulatory requirements. Before medical devices can be patched, the device manufacturer must approve and validate the patch. Therefore, they must be excluded from automated patching programs and handled through a separate, vendor-coordinated process. Automatically patching medical devices without manufacturer authorization poses a direct patient safety risk, making their exclusion the critical first step.
Topics
Community Discussion
No community discussion yet for this question.